CVE-2007-5686
EPSS 0.15%
Description
initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts. NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers.
How to fix CVE-2007-5686
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/shadow—no fix listed
Is CVE-2007-5686 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0